CtrlK
BlogDocsLog inGet started
Tessl Logo

repo-audit

Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets. Triggered when users ask about Git analysis, code hotspots, who owns what code, secret scanning, security audits of commit history, or optimizing code review assignments.

70

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, well-structured tool skill: three clearly sectioned scripts, each with an executable usage line, a complete option table, and verified bundle files. The only improvements are minor — one example invocation with real arguments and sample output per tool, and trimming the redundant Use Cases/rationale lines.

Suggestions

Add one copy-paste-ready example invocation per tool with concrete arguments and expected output (e.g. `bash scripts/hotfiles.sh --repo ./my-project --top 10 --since 2024-01-01 --format json`) to lift actionability from mostly-executable to fully executable.

Trim the 'spot:' rationale bullets under hotspot analysis and fold the Use Cases section into the description trigger clause — both restate knowledge Claude already has or content already in the frontmatter.

Clarify when to pick `--severity` levels in secret-scan.sh, e.g. one line noting that `medium` filters generic pattern matches that are often false positives.

DimensionReasoningScore

Conciseness

The body is dominated by compact usage commands and option tables with almost no padding, but includes minor trims: rationale bullets Claude already knows ("frequent changes = potential instability") and a Use Cases section that restates the description. Not 5 because those few lines could be cut; not 3 because there is no real over-explanation.

4 / 5

Actionability

Each tool ships an executable command ("bash scripts/hotfiles.sh [options]") plus a complete option table with defaults and output formats, and the referenced scripts exist and match the documented interfaces. Not 5 because no fully instantiated example invocation (e.g. `--top 10 --since 2024-01-01 --format json`) or sample output is shown for the common cases.

4 / 5

Workflow Clarity

Each of the three analyses is a single, unambiguous command with all options and defaults documented; the scripts are read-only so no validation checkpoints are required. Matches the simple-skill exception (single unambiguous action); not 4 because nothing about the per-tool workflow is missing or implicit.

5 / 5

Progressive Disclosure

SKILL.md is a clean overview with one section per script, and every referenced path (scripts/hotfiles.sh, scripts/ownership.sh, scripts/secret-scan.sh) resolves to a real bundle file — references are one level deep and well signaled. Not 4 because there are no organization gaps: implementation detail lives entirely in the scripts and nothing that belongs elsewhere is inlined.

5 / 5

Total

18

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

Strong description: concrete three-part capability statement in third person voice, followed by an explicit trigger clause with natural user phrases. Only minor gaps in trigger synonym coverage and slight overlap risk from the broad "Git analysis" term.

DimensionReasoningScore

Specificity

"identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets" lists three specific concrete actions that comprehensively cover the skill's capabilities. Not 4 because coverage is complete rather than having minor gaps; not below because every action is concrete rather than generic.

5 / 5

Completeness

Explicitly answers both what ("identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets") and when ("Triggered when users ask about Git analysis, code hotspots, who owns what code, secret scanning..."). Matches the 5 anchor with concrete trigger phrases, so no lower score applies.

5 / 5

Trigger Term Quality

Triggers include natural phrases users would say: "Git analysis", "code hotspots", "who owns what code", "secret scanning", "security audits of commit history", "optimizing code review assignments". Not 5 because a few natural synonyms are missing (e.g. "code ownership", "tech debt", "refactoring candidates").

4 / 5

Distinctiveness Conflict Risk

The git-history niche ("security audits of commit history", "who owns what code") is mostly distinct from other skills. Not 5 because the broad trigger "Git analysis" and "optimizing code review assignments" could overlap with generic git-helper or code-review skills.

4 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.